Veracode Announces VERAFIED™ Mark of Software Security for CWE/SANS Top 25 - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Get our newsletter
Order Prints
July 28, 2010
Share
Share
Post
Email

Veracode Announces VERAFIED™ Mark of Software Security for CWE/SANS Top 25

New Mark Indicates Software Has Been Independently Assessed for the CWE/SANS Top 25 Most Dangerous Software Errors

BURLINGTON, Mass.--(BUSINESS WIRE)-- Veracode, Inc., the world’s leader in cloud-based application risk management, today unveiled the new VERAFIED™ High Assurance mark of software application security for the CWE/SANS Top 25 Most Dangerous Software Errors. This prominent industry “seal of approval” indicates to a software provider’s customers and partners that an application has been independently assessed and that the testing did not detect exploitable software weaknesses identified in the list of the Top 25 Most Dangerous Software Errors as defined by the MITRE Common Weakness Enumeration (CWE) project that is sponsored by the US Federal Government. The independent high assurance assessment is performed with SecurityReview®, Veracode’s patented cloud-based automated security verification service, and complemented by manual penetration testing to identify flaws in business logic and design.

Software providers whose applications earn the VERAFIED mark may display it as an indicator to customers of their successful efforts to eliminate known, dangerous vulnerabilities. Additionally, the application may be identified with a VERAFIED High Assurance mark in Veracode’s VERAFIED Software Directory. CIOs, CISOs and others who acquire software may also use the mark as a threshold for security quality delivered by commercial, outsourced or open source suppliers.

“Among the most important things that can be done to improve software security is for buyers of software to require evidence of an acceptable minimum level of security that is able to be substantiated by a credible independent source,” said Joe Jarzombek, director for software assurance, National Cyber Security Division, Department of Homeland Security. “We support qualification and test activities that enable consumers of software and procurement groups to make better informed decisions based on a standard benchmark of software security. We applaud industry-led efforts that leverage the use of our US Federal Government-sponsored CWE to unambiguously make statements about mitigating software security risk exposures.”

To earn the VERAFIED High Assurance mark for the CWE/SANS Top 25 Most Dangerous Software Errors, software providers submit their final integrated application – binary or bytecode – to Veracode SecurityReview for assessment. The application is analyzed by Veracode’s patented cloud-based automated security verification service and then subjected to additional manual penetration testing by Veracode or its partners. Following the remediation of any vulnerabilities of severity medium or higher, as defined by FIRST’s CVSS vulnerability scoring system, and any identified vulnerabilities that are errors included in the Top 25 Most Dangerous Software Errors list compiled by MITRE and SANS and a consortium of other organizations, the application is then resubmitted to Veracode for complete security regression testing and verification. Given the ad hoc approach to security testing done by most organizations today, this consistent and repeatable framework and process enables software suppliers to differentiate applications that are VERAFIED for CWE/SANS Top 25 compliance and display the mark that demonstrates they have applied diligent efforts to find and remediate all known dangerous vulnerabilities.

“It is well established that the software supply chain poses a significant amount of unknown risk to every enterprise’s reputation and business continuity,” said Matt Moynahan, CEO of Veracode. “By displaying the VERAFIED mark for CWE/SANS Top 25 to indicate their developers’ vigorous efforts to eliminate dangerous software errors, commercial software providers, open source projects and outsourced software suppliers can differentiate themselves as good partners in the effort to reduce application-related risk.”

About Veracode

Veracode is the world’s leader in cloud-based application risk management. With patented binary code analysis, dynamic Web assessments and developer e-learning, Veracode SecurityReview® is the most accurate and cost-effective way to independently verify application security in both internally developed applications and third-party software without requiring source code or expensive tools. Veracode provides the most simple, complete way to implement security best practices, reduce operational cost and comply with internal security policies or external standards such as OWASP Top 10, Top 25 and PCI. Veracode works with global organizations across multiple vertical industries including Barclays PLC, California Public Employees’ Retirement System (CalPERS), Computershare and the Federal Aviation Administration (FAA). For more information, visit www.veracode.com, follow on Twitter @Veracode or read the ZeroDay Labs™ blog.

Copyright © 2010 Veracode, Inc.All Rights Reserved.All other brand names, product names, or trademarks belong to their respective holders.

fama PR
Liz Campbell, 617-758-4149
email: [email protected]

Source: Veracode

Advisor News

  • Using digital retirement modeling to strengthen client understanding
  • Fear of outliving money at a record high
  • Cognitive decline is a growing threat to financial security
  • Two lessons career changers wish they knew before starting the CFP journey
  • Americans less confident about retirement as worries grow
More Advisor News

Annuity News

  • CareScout Joins Ensight™ Intelligent Quote LTC & Life Marketplace
  • Axonic Insurance Annuities, Built for Banks, Broker-Dealers and RIAs, Now Available through WealthVest.
  • Allianz Life Adds New Accumulation-Focused Fixed Index Annuities
  • Allianz Life adds new accumulation-focused FIAs
  • Industry objects to ‘tone and tenor’ of draft NAIC Annuity Buyer’s Guide
More Annuity News

Health/Employee Benefits News

  • After health insurance subsidies end, 30,000 Idahoans will be uninsured, government report says
  • Georgia’s ACA enrollment plunges, raising concerns for rural hospitals
  • Pending cuts to Georgia Medicaid payments could affect children who need therapy
  • Orange schools, teachers union at impasse over health insurance
  • Miami judge sides with cancer patient, orders insurer to cover pricey treatment
More Health/Employee Benefits News

Life Insurance News

  • Agam Capital and 1823 Partners Announce Strategic Partnership to Provide Life Insurers with an End-to-End Value Chain Solution
  • AM Best Revises Outlooks to Positive for Western & Southern Financial Group, Inc. and Its Subsidiaries
  • Principal Financial Group Announces First Quarter 2026 Results
  • SBLI Enhances its OmniTrak Term to Deliver Faster Decisions, More Client Coverage, and Improved Pricing
  • Life insurance premium surges, but coverage is still falling short for many
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Protectors Vegas Arrives Nov 9th - 11th
1,000+ attendees. 150+ speakers. Join the largest event in life & annuities this November.

A FIA Cap That Stays Locked
CapLock™ from Oceanview locks the cap at issue for 5 or 7 years. No resets. Just clarity.

Aim higher with Ascend annuities
Fixed, fixed-indexed, registered index-linked and advisory annuities to help you go above and beyond

Unlock the Future of Index-Linked Solutions
Join industry leaders shaping next-gen index strategies, distribution, and innovation.

Leveraging Underwriting Innovations
See how Pacific Life’s approach to life insurance underwriting can give you a competitive edge.

Bring a Real FIA Case. Leave Ready to Close.
A practical working session for agents who want a clearer, repeatable sales process.

Press Releases

  • RFP #T01325
  • RFP #T01325
  • RFP #T01825
  • RFP #T01825
  • RFP #T01525
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet